Conversation
|
🌿 Preview your docs: https://nvidia-preview-pr-3244.docs.buildwithfern.com/openshell |
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
|
Label |
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
The startup repair that creates version-one policy history for legacy sandboxes propagated validation failures, so a single stored policy that no longer passes current validation rules prevented the gateway from starting. Skip such sandboxes with a warning and a completion summary so they keep the pre-repair behavior where only their own configuration reads report the failure. Store errors remain fatal. Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Fleet-wide configuration changes spawned one snapshot build per connected sandbox and component with no concurrency limit, so a global setting or provider change issued every store query and credential-driver call at once. Gate builds behind a semaphore sized from the database pool and start the build deadline only once a permit is held. Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Sandboxes keep their supervisor binary until they are recreated, so a gateway upgrade meets supervisors that predate the handshake and report revision zero. Rejecting them severs every running sandbox with no automatic recovery. Accept revision zero for one release, log a warning per session, and count them in openshell_supervisor_protocol_legacy_sessions_total. The supervisor mirrors the allowance for gateways that predate the handshake. Add a shared ConnectSupervisor test harness and handler-level tests for legacy acceptance and unknown-revision rejection. Move the skill troubleshooting paragraph out of the numbered deployment list so the list renders. Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
e7729ec to
70773d3
Compare
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
|
All contributors have signed the DCO ✍️ ✅ |
7f704dd to
43d7b28
Compare
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
pimlock
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
I reconciled the current head against the full Gator feedback ledger and reviewed the author-only delta since 8bf93ead in critical-only mode. The earlier fanout-bounding obligation remains resolved, the new delta only updates the repairable invalid-policy snapshot test after upstream integration, and no new Critical defect was found. Required current-head checks, including E2E, are green.
Action required: a maintainer must review and approve the PR.
Blocking findings:
- No blocking findings remain
Carried findings:
- None
Gator metadata
- Validation: Project-valid Stage 1 of accepted issue #1731; the current implementation remains within the reviewed gateway/supervisor configuration-delivery scope.
- Docs: Architecture, gateway reference, and troubleshooting guidance are updated for the current behavior.
- Checks: OpenShell Branch Checks, Helm Lint, Trivy Changes, DCO, and E2E are green for the current head.
- E2E:
test:e2eis applied and the current-head E2E suite completed successfully. - Head SHA:
bd9f91e593c2096542599aebaad43a2c179426e9 - Base SHA:
d91b1999a0f26c07b652652fcc3475bf3388d2c6 - Merge base SHA:
d91b1999a0f26c07b652652fcc3475bf3388d2c6 - Patch ID:
07916ac6bfc22b10c3571859fce1a82996b3149b - Gator payload:
9 - Review mode:
critical_only - Previous reviewed SHA:
8bf93eadd823357a2adaed5621b63dca63e6dc91 - Review budget exhausted: yes
- Maintainer decision required: no
- Next state:
gator:approval-needed
Summary
Add Stage 1 of gateway-pushed configuration over
ConnectSupervisor. The gateway sends complete sandbox configuration and provider-environment snapshots; supervisors receive them while polling remains authoritative.Configuration delivery flow
flowchart TD A[Configuration mutation] --> B[Commit authoritative state] B --> C[Notify scheduler of affected scope and component] C --> D[Coalesce notifications and build latest full snapshot] D --> E[Push snapshot over ConnectSupervisor] E --> F[Supervisor receives but ignores snapshot in Stage 1] B --> G[Existing polling path] G --> H[Supervisor applies configuration]Related Issue
Part of #1731. Replaces #2967. Stage 2 will apply snapshots and acknowledge revisions; Stage 3 will add durable completion semantics and remove polling.
Changes
Testing
Postgres-specific concurrency coverage requires
OPENSHELL_TEST_POSTGRES_URLand was not run.Checklist